Export limit exceeded: 400623 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (400623 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-56098 1 Redhat 3 Satellite, Satellite Capsule, Satellite Utils 2026-10-01 4.3 Medium
A flaw was found in rubygem-katello. The RegistryProxiesController in Katello contains an authorization bypass vulnerability due to an execution fall-through in the registry_authorize filter. While the application identifies unauthorized requests and triggers an error response via the unauthorized method, it fails to halt the execution of the current code path (missing return statement). This failure in the control flow allows the application to proceed into subsequent business logic and database validation filters. Consequently, the application reveals its internal state through differential responses, allowing an unprivileged attacker to enumerate valid Users, Organizations, and Products across the entire instance.
CVE-2026-56097 1 Redhat 3 Satellite, Satellite Capsule, Satellite Utils 2026-10-01 6.5 Medium
A flaw was found in rubygem-katello. An SQL injection vulnerability exists in the Red Hat Satellite Katello Registry Proxy. The application fails to sanitize input parameters used in database queries within the RegistryProxiesController. The methods check_blob_push_org_label and get_matching_products_from_org take user-supplied labels directly from the request path and interpolate them into raw SQL fragments. This flaw is accessible to a user with only the create_personal_access_tokens permission, even if the user access is restricted, with no Organization or Location assigned.
CVE-2026-12545 1 Redhat 3 Satellite, Satellite Capsule, Satellite Utils 2026-10-01 6.7 Medium
A flaw was found in rubygem-hammer_cli. A command injection vulnerability exists in Hammer CLI and the Railties (Ruby on Rails) component distributed with Satellite due to the insecure interpolation of the $EDITOR environment variable into the Ruby system() method. By passing a single interpolated string to system(), the application invokes a system shell (/bin/sh) that interprets shell metacharacters (e.g., ;, |, &).
CVE-2026-12542 1 Redhat 3 Satellite, Satellite Capsule, Satellite Utils 2026-10-01 5.3 Medium
A flaw was found in Foreman. The foreman-tail utility is vulnerable to OS command injection due to the unsafe use of the eval command. The script takes user-supplied arguments and incorporates them directly into a string that is then executed by eval to expand file paths. Because the input is not sanitized or quoted, a local attacker can inject shell metacharacters (e.g., ;, &, |) to execute arbitrary system commands.
CVE-2026-65640 1 Wordpress 1 Wordpress 2026-10-01 N/A
WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level user or higher. Prerequisites: * Imagick and Ghostscript in use on the server * A malicious user with the `upload_files` capability This issue affects all versions of WordPress. Version 7.0.4 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7.
CVE-2026-88467 2026-10-01 6.2 Medium
CRMEB Knowledge-Paid System crmeb_zzff_class 1.4.4 has a backend verification function that returns the wrong type of value, causing errors and leaking sensitive information.
CVE-2026-51883 1 Chatchat-space 1 Langchain-chatchat 2026-10-01 N/A
The knowledge base creation and document upload interfaces in Langchain-Chatchat 0.3.0;0.3.1 is vulnerable to path traversal. An attacker can inject path traversal sequences (such as `..\`) into the `knowledge_base_name` parameter to write knowledge base content to arbitrary locations outside the configured knowledge base root directory.
CVE-2026-51886 2026-10-01 N/A
langflow-ai langflow v1.9.3 is affected by: Code Injection. The impact is: execute arbitrary code (remote). The component is: src/backend/base/langflow/api/v1/validate.py:validate-post_validate_code-a-real-authenticated-http-post-to-api-v1. The attack vector is: Attack surface: HTTP or browser-backed service path. A public-facing route accepts raw Python source and forwards it into a server-side compile/exec validation path without any visible entitlement guard. ¶¶ A weakness has been identified in langflow-ai langflow up to 1.9.3. langflow contains a code injection vulnerability in validate-post_validate_code-a-real-authenticated-http-post-to-api-v1 (src/backend/base/langflow/api/v1/validate.py:13). An authenticated attacker can execute arbitrary Python code on the server by submitting malicious code to the /api/v1/validate/code endpoint, which directly executes user-supplied code without sandboxing or security controls.
CVE-2026-51895 1 Infiniflow 1 Ragflow 2026-10-01 N/A
Ragflow 0.24.0 and prior contains improper access control in update_metadata_setting (api/apps/kb_app.py). Depending on the exposed entry, an attacker can perform unauthorized cross-session or privilege-crossing operations.
CVE-2026-71452 1 Johnson Controls 1 Easyio Fs32 2026-10-01 N/A
- OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows OS Command Injection. This issue affects EasyIO FS32: before 3.0b63.
CVE-2026-71448 1 Johnson Controls 1 Easyio Fs32 2026-10-01 N/A
: Insecure Default Initialization of Resource vulnerability in Johnson Controls EasyIO FS32 allows : Authentication Abuse. This issue affects EasyIO FS32: before 3.0b63.
CVE-2026-64893 1 Johnson Controls 1 Easyio Neo 2026-10-01 N/A
- Cleartext Transmission of Sensitive Information vulnerability in Johnson Controls EasyIO NEO allows - Man In the Middle Attack. This issue affects EasyIO NEO: before 3.3b25.
CVE-2026-86345 1 Redhat 2 Directory Server, Enterprise Linux 2026-10-01 9 Critical
A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted LDAP message that is processed after the TLS upgrade and whose response is delivered to the client in place of the client's own pending operation's response, due to messageID collision. This can cause a client application to treat a failed authentication (bind) attempt as successful.
CVE-2026-96659 1 Redhat 3 Satellite, Satellite Capsule, Satellite Utils 2026-10-01 9.1 Critical
A flaw was found in Foreman. This vulnerability allows an authenticated user with low-level Viewer permissions to cause unauthorized information disclosure by submitting requests to template preview endpoints. By exploiting this issue, the user can access sensitive data, such as host root passwords. Furthermore, under insecure system configurations where Safemode protections are disabled, the flaw may allow the user to execute arbitrary commands as the Foreman system account.
CVE-2026-12544 2 Redhat, Theforeman 4 Satellite, Satellite Capsule, Satellite Utils and 1 more 2026-10-01 7.7 High
A flaw was found in Foreman. The foreman-rake initialization logic in /usr/share/foreman/config/settings.rb contains a vulnerable code pattern where configuration data is processed through two distinct executable layers. This creates a multi-stage execution chain that allows for both Server-Side Template Injection (SSTI) and insecure deserialization. This vulnerability can lead to remote code execution, total infrastructure compromise and supply chain risk.
CVE-2026-12541 1 Redhat 3 Satellite, Satellite Capsule, Satellite Utils 2026-10-01 8.2 High
A flaw was found in Foreman. OS command injection vulnerabilities exist in the foreman-rake db:dump and db:import_dump tasks. The application fails to properly sanitize user-supplied input in the destination parameter (during backups) and the file parameter (during imports) before passing them to a Ruby system() call for execution. An attacker with permissions to execute foreman-rake (e.g., via a restricted sudo configuration) can append malicious shell commands to the provided file paths.
CVE-2026-12540 1 Redhat 3 Satellite, Satellite Capsule, Satellite Utils 2026-10-01 8.2 High
A flaw was found in Foreman. A command injection vulnerability exists in the foreman-rake errors:fetch_log task. The request_id parameter is passed to an underlying system command (typically grep) without adequate shell neutralization. While the task is intended to fetch specific log entries, an attacker with sudo permissions to execute this rake task can inject shell metacharacters (such as ;, ", or |) to break out of the intended command and execute arbitrary code.
CVE-2026-12423 1 Redhat 3 Satellite, Satellite Capsule, Satellite Utils 2026-10-01 7.5 High
A flaw was found in Foreman. The Red Hat Satellite /unattended/provision API endpoint is vulnerable to an authentication bypass due to a semantic logic flaw in host_verifier.rb. The application verifies the database state of a provisioning token rather than its actual presence in the incoming HTTP request. Because a host actively undergoing provisioning has an unexpired token in the database, the server's valid_host_token? method evaluates to true, granting access to the kickstart template even if the requester provides no token at all in the URL.
CVE-2026-12405 1 Redhat 3 Satellite, Satellite Capsule, Satellite Utils 2026-10-01 8.8 High
A flaw was found in rubygem-foreman_remote_execution. A command injection vulnerability exists in the Red Hat Satellite API (/api/v2/job_invocations). When a job template has the effective_user property marked as overridable: true, the application fails to properly sanitize the effective_user input provided during the API request. The exploitation does not rely on the content or logic of the Job Template/playbook itself; rather, the injection occurs during the instantiation of the job execution environment by the Satellite server. An attacker with permissions to execute job templates can inject arbitrary shell commands into this parameter, which are executed on the target infrastructure with the privileges of the execution user.
CVE-2026-96658 1 Redhat 3 Satellite, Satellite Capsule, Satellite Utils 2026-10-01 9.9 Critical
A flaw was found in Foreman. An authenticated attacker with low-level permissions can achieve remote code execution (RCE) by bypassing the safemode sandbox within the templating engine. Due to improper handling of delegated methods, an attacker can append unauthorized functions to the allowed execution list, enabling them to run arbitrary commands on the hosting server.